Vulnerability index

Browse CVEs

17 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

H2o HIGH 8.2
CVE-2024-8616

In h2oai/h2o-3 version 3.46.0, the `/99/Models/{name}/json` endpoint allows for arbitrary file overwrite on the target server. The vulnerability aris…

No fix yet
Fix from $1,950 2025-03-20
H2o HIGH 7.5
CVE-2024-8062

A vulnerability in the typeahead endpoint of h2oai/h2o-3 version 3.46.0 allows for a denial of service. The endpoint performs a `HEAD` request to ver…

No fix yet
Fix from $1,950 2025-03-20
H2o HIGH 7.5
CVE-2024-7768

A vulnerability in the `/3/ImportFiles` endpoint of h2oai/h2o-3 version 3.46.1 allows an attacker to cause a denial of service. The endpoint takes a …

No fix yet
Fix from $1,950 2025-03-20
H2o HIGH 7.5
CVE-2024-7765

In h2oai/h2o-3 version 3.46.0.2, a vulnerability exists where uploading and repeatedly parsing a large GZIP file can cause a denial of service. The s…

No fix yet
Fix from $1,950 2025-03-20
H2o HIGH 7.1
CVE-2024-6854

In h2oai/h2o-3 version 3.46.0, the endpoint for exporting models does not restrict the export location, allowing an attacker to export a model to any…

No fix yet
Fix from $1,950 2025-03-20
H2o MEDIUM 6.5
CVE-2024-6863

In h2oai/h2o-3 version 3.46.0, an endpoint exposing a custom EncryptionTool allows an attacker to encrypt any files on the target server with a key o…

No fix yet
Fix from $1,600 2025-03-20
H2o HIGH 7.5
CVE-2024-10549

A vulnerability in the `/3/Parse` endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) attack. The endpoint uses a user-spec…

No fix yet
Fix from $1,950 2025-03-20
H2o HIGH 7.5
CVE-2024-10550

A vulnerability in the `/3/ParseSetup` endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) attack. The endpoint applies a u…

No fix yet
Fix from $1,950 2025-03-20
H2o HIGH 7.5
CVE-2024-10572

In h2oai/h2o-3 version 3.46.0.1, the `run_tool` command exposes classes in the `water.tools` package through the `ast` parser. This includes the `XGB…

No fix yet
Fix from $1,950 2025-03-20
H2o CRITICAL 9.8
CVE-2024-8862

A vulnerability, which was classified as critical, has been found in h2oai h2o-3 3.46.0.4. This issue affects the function getConnectionSafe of the f…

No fix yet
Fix from $2,300 2024-09-14
H2o MEDIUM 5.3
CVE-2024-5550

In h2oai/h2o-3 version 3.40.0.4, an exposure of sensitive information vulnerability exists due to an arbitrary system path lookup feature. This vulne…

No fix yet
Fix from $1,600 2024-06-06
H2o HIGH 7.1
CVE-2024-1456

An S3 bucket takeover vulnerability was identified in the h2oai/h2o-3 repository. The issue involves the S3 bucket 'http://s3.amazonaws.com/h2o-train…

No fix yet
Fix from $1,950 2024-04-16
H2o HIGH 8.2
CVE-2023-6569

External Control of File Name or Path in h2oai/h2o-3

No fix yet
Fix from $1,950 2023-12-14
H2o HIGH 7.5
CVE-2023-6038

A Local File Inclusion (LFI) vulnerability exists in the h2o-3 REST API, allowing unauthenticated remote attackers to read arbitrary files on the ser…

No fix yet
Fix from $1,950 2023-11-16
H2o HIGH 7.1
CVE-2023-6017

H2O included a reference to an S3 bucket that no longer existed allowing an attacker to take over the S3 bucket URL.

No fix yet
Fix from $1,950 2023-11-16
H2o MEDIUM 5.4
CVE-2023-6013

H2O is vulnerable to stored XSS vulnerability which can lead to a Local File Include attack.

No fix yet
Fix from $1,600 2023-11-16
H2o CRITICAL 9.8
CVE-2023-6016EPSS 31%

An attacker is able to gain remote code execution on a server hosting the H2O dashboard through it's POJO model import feature.

No fix yet
Fix from $2,300 2023-11-16